First published: Fri Jan 31 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leduchuy89vn Affiliate Tools Việt Nam allows Reflected XSS. This issue affects Affiliate Tools Việt Nam: from n/a through 0.3.17.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
leduchuy89vn Affiliate Tools Việt Nam | <=0.3.17 | |
WordPress Affiliate Tools Việt Nam plugin | <=0.3.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-23759 is considered moderate due to the reflected cross-site scripting (XSS) vulnerability.
To fix CVE-2025-23759, upgrade Affiliate Tools Việt Nam to version 0.3.18 or later.
CVE-2025-23759 affects the Affiliate Tools Việt Nam plugin versions ranging from n/a to 0.3.17.
Yes, CVE-2025-23759 can potentially lead to user data exposure through reflected XSS attacks.
Reflected XSS vulnerabilities like CVE-2025-23759 are commonly found in web applications that do not properly validate user input.